PE Studio aplicado a alguns executáveis
EXECUTÁVEL: OblivionLauncher.exe
PE Studio aplicado a alguns executáveis
EXECUTÁVEL: OblivionLauncher.exe
Procedência executável: Torrent
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Thu Apr 06 15:25:44 2006 | UTC -footprint (sha256):2AB982D924FBBF4B704F95E001842DC83BF95DEE56CEF26141531E4DB758159E -signature : Microsoft Visual C++ 7.0 MFC -cpu : 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: Bkav; W32.AIDetectMalware
-o que aponta no MITRE ATT&CK :
Execution TA0002 Defense Evasion TA0005 Discovery TA0007
SEÇÃO STRINGS: -total de strings: 15035
SEÇÃO IMPORTS: -os 3 primeiros importas com flags, e seu grupo (coluna grupo)
WritePrivateProfileStringA — grupo registry
GetCurrentProcessId — grupo reconnaissance
GlobalMemoryStatus — grupo memory
==============================================
EXECUTÁVEL: gta_sa.exe
Procedencia executável: torrent
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Thu Apr 28 15:31:22 2005 | UTC -footprint: A559AA772FD136379155EFA71F00C47AAD34BBFEAE6196B0FE1047D0645CBD26 -signature: Microsoft Visual C++ 7.0 MFC -cpu : 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:
Bkav / W32.AIDetectMalware
-o que aponta no MITRE ATT&CK :
Execution TA0002 Persistence TA0003 Privilege Escalation TA0004 Defense Evasion TA0005 Credential Access TA0006 Discovery TA0007 Collection TA0009 Command and Control TA0011
SEÇÃO STRINGS: -total de strings: 213.732
SEÇÃO IMPORTS: -os 3 primeiros importas com flags, e seu grupo (coluna grupo)
GetOverlappedResult — grupo synchronization
RegCreateKeyExA — grupo registry
RegSetValueExA — grupo registry
==============================================
EXECUTÁVEL: PlayGTAV.exe
Procedencia executável: torrent
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Sun Mar 22 12:24:23 2020 | UTC -footprint: 9D4D78F8249CC4F45026F6C545499C6F5AA6DB87852798B82EF2FC788D310290 -signature : N/A -cpu: 64-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:
APEX — Malicious
Cynet — Malicious
TrendMicro-HouseCall — TROJ_GEN.R002V01K323
SEÇÃO STRINGS: -total de strings: 7870
SEÇÃO IMPORTS:
WriteFile — group file
CreateProcessA — group — execution,T1106 | Execution through API
RtlLookupFunctionEntry — group execution
==============================================
EXECUTÁVEL: devcpp.exe
Procedencia executável: site oficial
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Fri Jun 19 22:22:17 1992 | UTC -footprint: 5E490F306CACE14810C9FDABF7E30A2C2E1941BEDD5E00C54B24E208926527E1 -signature — exemplo : N/A -cpu: 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: N/A
-o que aponta no MITRE ATT&CK: N/A
SEÇÃO STRINGS: -total de strings: 54336
SEÇÃO IMPORTS:

==============================================
EXECUTÁVEL: Wireshark.exe
Procedencia executável:site original
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed Aug 23 19:07:58 2023 | UTC -footprint: 85947539A421A8A4C547A09E4351799BBC73B89E175DDBA4CE6A0936BB07AF2E -signature — exemplo : Microsoft Visual C++ -cpu : 64-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total : N / A -o que aponta no MITRE ATT&CK: N/A
SEÇÃO STRINGS: -total de strings: N/A
SEÇÃO IMPORTS: N / A
==============================================
EXECUTÁVEL: aom.exe
Procedencia executável: cd rom
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Fri Apr 23 19:56:51 2004 | UTC -footprint: 34D66DCBBD9EB8174083E4C44C6FCC26F1E369653ABD446513727A0D86DFF29F -signature — exemplo : Microsoft Visual C++ v6.0 -cpu : 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

-o que aponta no MITRE ATT&CK:

SEÇÃO STRINGS: -total de strings: N / A
SEÇÃO IMPORTS: N / A
==============================================
EXECUTÁVEL: DB Browser for SQLite.exe
Procedencia executável: site original
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Thu Oct 10 13:12:07 2019 | UTC -footprint: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 -signature — exemplo : n /a -cpu: 64-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n /a
SEÇÃO STRINGS: -total de strings: n / a
SEÇÃO IMPORTS: n / a
==============================================
EXECUTÁVEL: uTorrent.exe
Procedencia executável: site oficial
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Tue Nov 21 03:20:03 2023 | UTC -footprint: 4089DAC808A6A0E8C4007185D64844503DED6606B6F063D769F65A9402ED57F5 -signature : UPX -> www.upx.sourceforge.net -cpu : 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

-o que aponta no MITRE ATT&CK:

SEÇÃO STRINGS: -total de strings: n/a
SEÇÃO IMPORTS: n/a
==============================================
EXECUTÁVEL: firefox.exe (tor browser )
Procedencia executável: site original
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: n/a -footprint: 53C54C98971CD0E1121FDFA4691E7EAA392A4EED09710EE15B269F7E22470C4E -signature: -cpu : 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:

SEÇÃO STRINGS: -total de strings: 26373
SEÇÃO IMPORTS:

==============================================
EXECUTÁVEL: ProtonVPN.exe
Procedencia executável: site original
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Mon Apr 17 09:13:48 2023 | UTC -footprint: 558E395C8D560BA2257836542CF54E1D491F35BBD90F1C710DD626AB94ED99B1 -signature: Microsoft .NET -cpu : 32-bit
SEÇÃO VIRUSTOTAL:
SEÇÃO STRINGS: -total de strings: n/a
SEÇÃO IMPORTS: n/a
==============================================
EXECUTÁVEL: VirtualBox.exe
Procedencia executável: site oficial
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed Jan 11 16:40:35 2023 | UTC -footprint: 0E7C8FD7EA6E25989E611FFA93CD7671B830643A60481659A4B37741614FE536 -signature: n/a -cpu: 64-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total:
n/a
SEÇÃO STRINGS: -total de strings: n/a
SEÇÃO IMPORTS: n/a
==============================================
EXECUTÁVEL: Scratch Desktop
Procedencia executável: site original
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Mon Aug 05 17:24:45 2019 | UTC -footprint: 6200BB3C9B06DF65A27655F8A28A9143E5394F62FE12E893C9AA16785BCB6C97 -signature — exemplo : Microsoft Visual C++ -cpu: 32-bit
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n/a
SEÇÃO STRINGS: -total de strings: n/a
SEÇÃO IMPORTS: n/a
============================================== EXECUTÁVEL: 1001.exe (cd rom com 100 jogos)
Procedencia executável: CD de revista
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed May 14 16:53:28 1997 | UTC -footprint: 2E76C2B1DAA4706F87D81AAB426B4647919F9BAD410626D81E741BE082F46BDD -signature — exemplo : Microsoft Visual C 2.0 -cpu — 32 bits
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n/a
SEÇÃO STRINGS: -total de strings: 49410
SEÇÃO IMPORTS:

==============================================
EXECUTÁVEL: Google Update Setup.exe
Procedencia executável: site original
SEÇÃO PRINCIPAL (PRIMEIRA): -compiler stamp: Wed Jan 10 02:10:49 2024 | UTC -footprint: 730A65C0941A611DA25B0782AC159870023D324C304C4DA52870D89A683882CB -signature: Microsoft Visual C++ -cpu: 32 bits
SEÇÃO VIRUSTOTAL: -antivirus, e o que foi apontato no virtus total: n/a
SEÇÃO STRINGS: -total de strings: 41028
SEÇÃO IMPORTS: -os 3 primeiros importas com flags, e seu grupo (coluna grupo)

메타데이터
- post_id
- 03f38303c71b
- slug
- pe-studio-aplicado-a-alguns-executáveis-03f38303c71b
- url
- https://medium.com/@heltonxh9/pe-studio-aplicado-a-alguns-execut%C3%A1veis-03f38303c71b
- canonical_url
- https://medium.com/@heltonxh9/pe-studio-aplicado-a-alguns-execut%C3%A1veis-03f38303c71b
- author_url
- https://medium.com/@heltonxh9
- status
- ok
- fetched_at
- 2026-07-26 18:12:23